# Packetbeat performance and sizing

**URL:** <https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 18, 2021, 6:08am UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769 "2021-08-18T06:08:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gintek](https://avatars.discourse-cdn.com/v4/letter/g/f05b48/32.png) [@gintek](https://discuss.elastic.co/u/gintek)\
**Post date:** [August 18, 2021, 6:08am UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769/1 "2021-08-18T06:08:14Z")

</div>

Hello,

I'm planning to use packetbeat on dedicated servers, getting the traffic from mirror ports on switch. Dedicated server will Virtual Machine with Linux of course.  
I couldn't find in documentation what resources is need to handle traffic: example 100Mbps, 1 Gbps or 10Gbps.  
Can you give we advise how to count what resources are needed ?  
Thanks,

---

<div class="post-metadata">

**Author:** ![PublicName](https://avatars.discourse-cdn.com/v4/letter/p/74df32/32.png) [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Post date:** [August 19, 2021, 9:20pm UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769/2 "2021-08-19T21:20:13Z")

</div>

I can only tell you off of first hand experience only. Packetbeat won't be your bottle neck. I've run it on a Celeron machine in a docker container feeding it close to 1Gb a sec and the CPU was never above 20%. Filebeat may be more beneficial depending on what your trying to capture. For instance Netflow traffic which is more detailed is under filebeat.

What will be your problem is how big your Elastic Cluster will be to suck up the data. I only capture DHCP,DNS events on 2 servers and HTTP/TLS on 2 others. It comes out to 29million events a day. After about a week that started to show that it was a lot of events...

Plan for what you want to capture first then look at how large your cluster will have to be in order to make use of the data.

---

<div class="post-metadata">

**Author:** ![gintek](https://avatars.discourse-cdn.com/v4/letter/g/f05b48/32.png) [@gintek](https://discuss.elastic.co/u/gintek)\
**Post date:** [August 20, 2021, 6:04am UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769/3 "2021-08-20T06:04:43Z")

</div>

Thanks a lot!  
I'll bear it in mind.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2021, 8:05am UTC](https://discuss.elastic.co/t/packetbeat-performance-and-sizing/281769/4 "2021-09-17T08:05:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
